CVE-2015-1349
published 2015-02-19CVE-2015-1349: named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows…
PriorityP336medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
22.17%
97.4th percentile
named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_server_v5.0.3 | — | — |
| debian | bind9 | < bind9 1:9.9.5.dfsg-9 (bookworm) | bind9 1:9.9.5.dfsg-9 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
osv5.4MEDIUM
vendor_debian5.4LOW
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-15:05.bind: BIND remote denial of service vulnerability
bsd_advisories·2015-02-25·CVSS 5.4
CVE-2015-1349 [MEDIUM] FreeBSD-SA-15:05.bind: BIND remote denial of service vulnerability
FreeBSD-SA-15:05.bind Security Advisory
The FreeBSD Project
Topic: BIND remote denial of service vulnerability
Category: contrib
Module: bind
Announced: 2015-02-25
Credits: ISC
Affects: FreeBSD 8.x and FreeBSD 9.x.
Corrected: 2015-02-18 22:20:19 UTC (stable/9, 9.3-STABLE)
2015-02-25 05:56:54 UTC (releng/9.3, 9.3-RELEASE-p10)
2015-02-18 22:29:52 UTC (stable/8, 8.4-STABLE)
2015-02-25 05:56:54 UTC (releng/8.4, 8.4-RELEASE-p24)
CVE Name: CVE-2015-1349
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Internet Domain Name Server.
II. Problem Description
BIND ser
Red Hat
bind: issue in trust anchor management can cause named to crash
vendor_redhat·2015-02-20·CVSS 5.4
CVE-2015-1349 [MEDIUM] CWE-391 bind: issue in trust anchor management can cause named to crash
bind: issue in trust anchor management can cause named to crash
named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.
A flaw was found in the way BIND handled trust anchor management. A remote attacker could use this flaw to cause the BIND daemon (named) to crash under certain conditions.
Statement: Red Hat Enterprise Linux 5 ships with both bind (9.3) packages which are not affected by this issue, and bind97 packages, which are affected by this issue.
Red Hat Enterprise Linux 5 is now in Productio
Ubuntu
Bind vulnerability
vendor_ubuntu·2015-02-18
CVE-2015-1349 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Jan-Piet Mens discovered that Bind incorrectly handled Trust Anchor
Management. A remote attacker could use this issue to cause bind to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2015-1349: bind9 - named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P...
vendor_debian·2015·CVSS 5.4
CVE-2015-1349 [MEDIUM] CVE-2015-1349: bind9 - named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P...
named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.
Scope: local
bookworm: resolved (fixed in 1:9.9.5.dfsg-9)
bullseye: resolved (fixed in 1:9.9.5.dfsg-9)
forky: resolved (fixed in 1:9.9.5.dfsg-9)
sid: resolved (fixed in 1:9.9.5.dfsg-9)
trixie: resolved (fixed in 1:9.9.5.dfsg-9)
Apple
CVE-2015-1349: OS X Server v5.0.3
vendor_apple·CVSS 5.4
CVE-2015-1349 [MEDIUM] CVE-2015-1349: OS X Server v5.0.3
Apple Security Update: About the security content of OS X Server v5.0.3
Product: OS X Server v5.0.3
CVE: CVE-2015-1349
Component: CVE-2015-1349
GHSA
GHSA-q3mx-v284-x6qr: named in ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2015-1349 [MEDIUM] GHSA-q3mx-v284-x6qr: named in ISC BIND 9
named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.
OSV
CVE-2015-1349: named in ISC BIND 9
osv·2015-02-19·CVSS 5.4
CVE-2015-1349 [MEDIUM] CVE-2015-1349: named in ISC BIND 9
named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0082.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150904.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150905.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00038.htmlhttp://marc.info/?l=bugtraq&m=143740940810833&w=2http://rhn.redhat.com/errata/RHSA-2015-0672.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:054http://www.mandriva.com/security/advisories?name=MDVSA-2015:165http://www.ubuntu.com/usn/USN-2503-1https://bugzilla.redhat.com/show_bug.cgi?id=1193820https://kb.isc.org/article/AA-01235https://kb.juniper.net/JSA10783https://kc.mcafee.com/corporate/index?page=content&id=SB10116https://security.gentoo.org/glsa/201510-01https://support.apple.com/HT205219http://advisories.mageia.org/MGASA-2015-0082.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150904.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150905.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00038.htmlhttp://marc.info/?l=bugtraq&m=143740940810833&w=2http://rhn.redhat.com/errata/RHSA-2015-0672.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:054http://www.mandriva.com/security/advisories?name=MDVSA-2015:165http://www.ubuntu.com/usn/USN-2503-1https://bugzilla.redhat.com/show_bug.cgi?id=1193820https://kb.isc.org/article/AA-01235https://kb.juniper.net/JSA10783https://kc.mcafee.com/corporate/index?page=content&id=SB10116https://security.gentoo.org/glsa/201510-01https://support.apple.com/HT205219
2015-02-19
Published